CVE-2018-20757: XSS
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as a Container name or Attribute name.
Other sources
MODX Revolution through v2.7.0-pl allows XSS via an extended user field such as Container name or Attribute name.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-20757?
CVE-2018-20757 has a medium severity rating due to its potential to allow cross-site scripting (XSS) attacks.
How do I fix CVE-2018-20757?
To fix CVE-2018-20757, upgrade MODX Revolution to version 2.7.1 or later, where the vulnerability has been patched.
What are the potential impacts of CVE-2018-20757?
The potential impacts of CVE-2018-20757 include unauthorized script execution on user interactions, possibly leading to session hijacking.
Who is affected by CVE-2018-20757?
CVE-2018-20757 affects all versions of MODX Revolution up to and including 2.7.0-pl.
How can I identify if I am vulnerable to CVE-2018-20757?
You can identify if you are vulnerable to CVE-2018-20757 by checking the version of your MODX Revolution installation and verifying if it is 2.7.0 or earlier.